Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vfp4-xx6m-7vf6

Опубликовано: 15 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Cryptographic Issues in ECK

Elastic Cloud on Kubernetes (ECK) versions prior to 1.1.0 generate passwords using a weak random number generator. If an attacker is able to determine when the current Elastic Stack cluster was deployed they may be able to more easily brute force the Elasticsearch credentials generated by ECK.

Пакеты

Наименование

github.com/elastic/cloud-on-k8s

go
Затронутые версииВерсия исправления

< 1.1.0

1.1.0

EPSS

Процентиль: 57%
0.00352
Низкий

7.5 High

CVSS3

Дефекты

CWE-335

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 5 лет назад

Elastic Cloud on Kubernetes (ECK) versions prior to 1.1.0 generate passwords using a weak random number generator. If an attacker is able to determine when the current Elastic Stack cluster was deployed they may be able to more easily brute force the Elasticsearch credentials generated by ECK.

CVSS3: 7.5
nvd
больше 5 лет назад

Elastic Cloud on Kubernetes (ECK) versions prior to 1.1.0 generate passwords using a weak random number generator. If an attacker is able to determine when the current Elastic Stack cluster was deployed they may be able to more easily brute force the Elasticsearch credentials generated by ECK.

EPSS

Процентиль: 57%
0.00352
Низкий

7.5 High

CVSS3

Дефекты

CWE-335